KlarComply provides the Customer with the services described in the subscription agreement (compliance dashboard, online training, evidence management under Regulation (EU) 2024/1689). In doing so, KlarComply processes personal data on behalf of the Customer. This agreement applies for the duration of the subscription and ends upon its termination; clause 7 (deletion) remains unaffected.
Storage, organisation and evaluation of data of the Customer's employees for the purposes of training management, certificate management, evidence management (AI inventory, policy details, acknowledgment logs) and access management. Details: Annex 1.
KlarComply processes the data exclusively on the Customer's documented instructions (Art. 28(3)(a) GDPR); the Customer's use of the platform features constitutes an instruction. If KlarComply considers an instruction unlawful, it shall inform the Customer without undue delay and may suspend execution.
The Customer grants general authorisation for the use of the sub-processors listed in Annex 3. KlarComply gives notice of intended changes; the Customer may object within 14 days on substantial data-protection grounds. Agreements pursuant to Art. 28 GDPR are in place with all sub-processors.
KlarComply assists the Customer, to the extent reasonable, in responding to data-subject requests (Art. 12–23), in securing the processing, in data protection impact assessments and in notification duties (Art. 32–36). KlarComply notifies the Customer of personal data breaches without undue delay.
After termination of the subscription, KlarComply deletes all personal data processed on behalf of the Customer within 30 days, unless a statutory retention duty applies. The Customer may back up its data beforehand via the dashboard's export/print functions. Issued certificates remain stored for public verification (legitimate interest of the certificate holders); the Customer may request their deletion.
KlarComply provides the Customer with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and enables audits — upon notice and at most once per year, except where there is specific cause. Evidence may be provided through current attestations/certifications of the sub-processors (e.g. SOC 2, ISO 27001).
Processing takes place in data centres in the EU (Frankfurt region, Germany). Where sub-processors established outside the EU are used (Annex 3), any transfer is based on EU standard contractual clauses or an adequacy decision (e.g. the EU-US Data Privacy Framework).
The law applicable to the subscription agreement also applies here. In case of conflict, this agreement prevails in data-protection matters. Should any provision be invalid, the remaining provisions remain in force.
| Data subjects | Employees, contact persons and, where applicable, external staff of the Customer |
|---|---|
| Data categories | Name, business email address, role; training progress and results (per cent); certificate data (name, company, date, check-ID); acknowledgment logs (who, what, when); details maintained by the Customer (AI inventory, contact person, rules) |
| No processing of | special categories under Art. 9 GDPR; such data must not be entered into the platform |
| Provider | Purpose | Registered office / region |
|---|---|---|
| Supabase Inc. | Database, authentication, server functions | USA · data stored in the EU (AWS Frankfurt) · SCC/DPF |
| Cloudflare Inc. | Website hosting, CDN, security | USA · EU delivery · SCC/DPF |
| MailerLite (UAB) | Newsletter/notifications (contact email only) | Lithuania (EU) |
Note: payment data is processed by Stripe Payments Europe Ltd. as an independent controller — it is not covered by this data processing agreement.
This agreement is concluded electronically (Art. 28(9) GDPR). Acceptance takes place in the KlarComply dashboard by the Customer's authorised signatory; time, name and contract version are logged verifiably. The binding text is the German version 1.0 (see klarcomply.com/avv).